{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/",
        "slug": "dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/"
        },
        "title": "Preserve HGS signing and encryption keys through certificate renewal",
        "summary": "What certificate-renewal constraint must be preserved for Host Guardian Service?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:15:10+00:00",
        "modified_at": "2026-09-08T18:23:27+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 200,
        "potentially_affected": "Administrators obtaining or renewing HGS signing and encryption certificates.",
        "dse_recommendation": "Prepare a renewal plan that explicitly preserves the required keys and identifies the authorized custodian.",
        "primary_source": {
            "name": "Obtain certificates for HGS",
            "url": "https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-obtain-certs",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>HGS uses signing and encryption certificates to protect the information needed to start shielded VMs. VM owners use the public certificate material to authorize the guarded environment. Microsoft recommends certificates from a trusted certification authority. The documentation also permits self-signed certificates for a lab environment. The HGS certificate requirements specify renewal with the same key. Microsoft warns that renewing with different keys prevents shielded VMs from starting. <a href=\"https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-obtain-certs\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the certificate roles, current keys, issuing authority, expiration dates, and all HGS nodes. Review the source’s complete cryptographic requirements and the key-storage provider before ordering replacements.</p>\n<h2>DSE recommendation</h2>\n<p>Prepare a renewal plan that explicitly preserves the required keys and identifies the authorized custodian. Have the guarded-fabric owner review how renewal differs from an intentional key-change project. Schedule a representative startup test and retain the approved recovery material before replacing certificates.</p>\n<h2>Verification</h2>\n<p>Inspect the renewed certificates and confirm the intended key relationship and deployment on the required nodes. Start a representative shielded VM through the approved guarded-host path and record HGS results. Treat an unexplained key change or startup failure as unresolved before completing the renewal.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-obtain-certs\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Obtain certificates for HGS</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nHGS uses signing and encryption certificates to protect the information needed to start shielded VMs. VM owners use the public certificate material to authorize the guarded environment. Microsoft recommends certificates from a trusted certification authority. The documentation also permits self-signed certificates for a lab environment. The HGS certificate requirements specify renewal with the same key. Microsoft warns that renewing with different keys prevents shielded VMs from starting. Microsoft documentation.\nApplicability\nIdentify the certificate roles, current keys, issuing authority, expiration dates, and all HGS nodes. Review the source’s complete cryptographic requirements and the key-storage provider before ordering replacements.\nDSE recommendation\nPrepare a renewal plan that explicitly preserves the required keys and identifies the authorized custodian. Have the guarded-fabric owner review how renewal differs from an intentional key-change project. Schedule a representative startup test and retain the approved recovery material before replacing certificates.\nVerification\nInspect the renewed certificates and confirm the intended key relationship and deployment on the required nodes. Start a representative shielded VM through the approved guarded-host path and record HGS results. Treat an unexplained key change or startup failure as unresolved before completing the renewal.\nOfficial references\nMicrosoft Learn: Obtain certificates for HGS. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nHGS uses signing and encryption certificates to protect the information needed to start shielded VMs. VM owners use the public certificate material to authorize the guarded environment. Microsoft recommends certificates from a trusted certification authority. The documentation also permits self-signed certificates for a lab environment. The HGS certificate requirements specify renewal with the same key. Microsoft warns that renewing with different keys prevents shielded VMs from starting. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-obtain-certs).\n\n## Applicability\n\nIdentify the certificate roles, current keys, issuing authority, expiration dates, and all HGS nodes. Review the source’s complete cryptographic requirements and the key-storage provider before ordering replacements.\n\n## DSE recommendation\n\nPrepare a renewal plan that explicitly preserves the required keys and identifies the authorized custodian. Have the guarded-fabric owner review how renewal differs from an intentional key-change project. Schedule a representative startup test and retain the approved recovery material before replacing certificates.\n\n## Verification\n\nInspect the renewed certificates and confirm the intended key relationship and deployment on the required nodes. Start a representative shielded VM through the approved guarded-host path and record HGS results. Treat an unexplained key change or startup failure as unresolved before completing the renewal.\n\n## Official references\n\n[Microsoft Learn: Obtain certificates for HGS](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-obtain-certs). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Preserve HGS signing and encryption keys through certificate renewal",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/",
                "headline": "Preserve HGS signing and encryption keys through certificate renewal",
                "description": "What certificate-renewal constraint must be preserved for Host Guardian Service?",
                "abstract": "What certificate-renewal constraint must be preserved for Host Guardian Service?",
                "articleBody": "Source facts\nHGS uses signing and encryption certificates to protect the information needed to start shielded VMs. VM owners use the public certificate material to authorize the guarded environment. Microsoft recommends certificates from a trusted certification authority. The documentation also permits self-signed certificates for a lab environment. The HGS certificate requirements specify renewal with the same key. Microsoft warns that renewing with different keys prevents shielded VMs from starting. Microsoft documentation.\nApplicability\nIdentify the certificate roles, current keys, issuing authority, expiration dates, and all HGS nodes. Review the source’s complete cryptographic requirements and the key-storage provider before ordering replacements.\nDSE recommendation\nPrepare a renewal plan that explicitly preserves the required keys and identifies the authorized custodian. Have the guarded-fabric owner review how renewal differs from an intentional key-change project. Schedule a representative startup test and retain the approved recovery material before replacing certificates.\nVerification\nInspect the renewed certificates and confirm the intended key relationship and deployment on the required nodes. Start a representative shielded VM through the approved guarded-host path and record HGS results. Treat an unexplained key change or startup failure as unresolved before completing the renewal.\nOfficial references\nMicrosoft Learn: Obtain certificates for HGS. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:15:10+00:00",
                "dateModified": "2026-09-08T18:23:27+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-121-preserve-hgs-signing-and-encryption-keys-through-certificate-renewal/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Preserve HGS signing and encryption keys through certificate renewal"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 200,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Obtain certificates for HGS",
                    "url": "https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-obtain-certs"
                }
            }
        ]
    }
}